NCC warns against YouTube-related malware


The Nigerian Communications Commission’s Computer Security Incident Response Team has warned those looking to acquire pirated software and resources that they risk becoming victims of cybercriminal gangs that are using AI-generated YouTube videos to distribute malware.

The NCC-CSIRT further warned in its advisory that the consequences of falling victim could be significant for individuals and organisations, resulting in critical damage like data theft, financial loss, identity theft, system damage, and reputation damage.

According to the NCC Director, Public Affairs, Reuben Muoka, in a statement on Sunday, the advisory stated that unsuspecting victims who watched these AI-generated tutorial videos would be duped into clicking on one of the links in the video description, which usually resulted in the download of data-stealing malware.

It said the number of YouTube videos containing such links had increased by 200-300% months on month since November 2022.

“To stimulate the interest of potential victims, video tutorials on how to pirate sought-after software such as AutoCAD, Adobe Photoshop, Adobe Premiere Pro, and other similar paid-for software are created. These videos are created with AI and feature humans with facial features that research has shown other humans find trustworthy.

“The tutorials in these videos are frequently bogus and steer viewers to links in the description that led to information-stealing malware like Raccoon, Vidar, and RedLine,” the advisory revealed.

It said malicious actors could create AI-generated videos that included hidden or disguised malware. These videos may appear to be harmless or even entertaining, but they can contain malicious code that can infect a viewer’s device when the video is downloaded or played.

“Cybercriminal actors can also use AI-generated videos to trick viewers into downloading malware. For example, they can create a video that appears to be a legitimate software update or security patch, but it contains malware that infects the viewer’s device.

“They equally use AI-generated videos to distribute phishing scams. They can create a video…

Source…